← Back

CVE-2007-4632

nvd nist
Published: Aug 31, 2007Modified: Apr 23, 2026

JSON object

Loading...
4.3
Vector
AV:A/AC:H/Au:N/C:P/I:P/A:P
Exploitability: 3.2 / Impact: 6.4
Source: NVD

Description

Cisco IOS 12.2E, 12.2F, and 12.2S places a "no login" line into the VTY configuration when an administrator makes certain changes to a (1) VTY/AUX or (2) CONSOLE setting on a device without AAA enabled, which allows remote attackers to bypass authentication and obtain a terminal session, a different vulnerability than CVE-1999-0293 and CVE-2005-2105.

Affected (3)

Products: Cisco: Ios
1 product
Ios
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 12.2e
Version 12.2f
Version 12.2s

References (6)

Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.